> ## Content Index
> Fetch the complete content index at: https://katecarruthers.com/llms.txt
> Use this file to discover other available public pages before exploring further.

# What to do if you’re the subject of a data breach
- URL: https://katecarruthers.com/what-to-do-if-youre-the-subject-of-a-data-breach/
- Published: 2022-09-24T13:20:38.000Z
- Updated: 2026-04-01T03:51:25.000Z
- Author: Kate Carruthers
- Tags: privacy, cybersecurity, #Migrated-1775015344493, #wp, #wp-post, #Import 2026-04-01 14:49

Just a few tips for folks who might be the subject to a major data breach (like the recent [Optus incident](https://www.theguardian.com/australia-news/2022/sep/24/optus-cyber-attack-how-do-you-know-if-your-identity-has-been-stolen-and-what-will-happen-to-your-data?ref=katecarruthers.com)):

- Start using [multi factor authentication](https://www.cyber.gov.au/mfa?ref=katecarruthers.com) (MFA) for all accounts if possible. DO NOT USE SMS BASED AUTHENTICATION unless you have no other choice. Here is an [explanation](https://www.theregister.com/2020/11/11/microsoft%5Fmfa%5Fwarning/?ref=katecarruthers.com) for the general badness of SIM based MFA.
- Start using a password manager so that you can have long and complex passwords. Also use a different password for each separate site. I recommend [Bitwarden](https://bitwarden.com/?ref=katecarruthers.com) or [1Password](https://1password.com/?ref=katecarruthers.com) ( they are good - I have no connection to either company).
- Ensure that you are using anti-virus and anti-malware tools, for Microsoft just turn on [Microsoft Defender](https://www.microsoft.com/en-au/windows/comprehensive-security?ref=katecarruthers.com) as it is good and it is free.
- Report as stolen any credit cards you used to pay bills with the company.
- If you want to store payment details on the company site then consider using something like [PayPal](https://www.paypal.com/?ref=katecarruthers.com) rather than storing your credit card details. Enable MFA on your PayPal account first though.
- Change any IDs you used to setup the account, e.g. passport, driver’s license, etc.
- Setup credit reporting accounts with email alerts so you can know if anyone is trying to obtain credit in your name. Read [this](https://www.idcare.org/fact-sheets/credit-bans-australia?ref=katecarruthers.com) and [this](https://assets.website-files.com/5af4dc294c01df9fc297c900/632e67b2ca8ee2c0a1e7361b%5FIDCARE%20Response%20Fact%20Sheet%20-%20Optus%20Data%20Breach.pdf?ref=katecarruthers.com).
- Setup a separate secured email account to receive emails from your financial institutions (Proton mail is good).
- Be vigilant with mobile phone calls from unknown numbers. Do not click any links in emails or text messages.
- Sign up for Troy Hunt's excellent Have I been pwned service [https://haveibeenpwned.com/](https://haveibeenpwned.com/?ref=katecarruthers.com)
- Check out [scam watch](https://www.scamwatch.gov.au/news-alerts/customers-warned-to-watch-out-for-scams-following-optus-data-breach?ref=katecarruthers.com), and their specific advice re the [Optus data breach](https://www.scamwatch.gov.au/types-of-scams/recent-scam-activity/optus-data-breach-scams?ref=katecarruthers.com)

And if you’re not sure what an attacker can do with your personal information here is a great rundown from Cam Wilson ( [@CAMERONWILSON](https://twitter.com/@cameronwilson?ref=katecarruthers.com)) via [Crikey](https://www.crikey.com.au/2022/09/30/optus-hack-data-breach-quiz/?ref=katecarruthers.com).